 |
rundll32.exe [path to DLL file], Do98Work |
(default)
Added by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rstrui.exe |
*Restore
Part of Windows System Restore and added as a RunOnce registry entry. Leave alone |
 |
rchost.exe |
.norton
Added by the BOXED-H TROJAN! |
 |
rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl |
123456
Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number |
 |
rundll32.exe D0CE0C16B1, D0CE0C16B1 |
98D0CE0C16B1
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
regedit -s ..win.dll |
@
Added by the SEEKER.K TROJAN! |
 |
reminder.exe |
@loha
Registration reminder for @loha@home E-mail utility |
 |
rundll32.exe E6F1873B.DLL, D9EBC318C |
A70F6A1D-0195-42a2-934C-D8AC0F7C08EB
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Reminder.exe |
Acer Tour Reminder
Popup reminder to take the tour of your new Acer laptop |
 |
RunDll32.exe [path] Blocker.dll, Run |
Acronis Popup Blocker
Part of Acronis Privacy Expert - anti-spyware and security suite |
 |
READER~1.EXE |
Adobe Acrobat
Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
 |
Reader_sl.exe |
Adobe Reader Speed Launch
Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
 |
READER~1.EXE |
Adobe Reader Speed Launch
Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
 |
Reader_sl.exe |
Adobe Reader Speed Launcher
Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
 |
rundtl.exe |
AdobeManager
Detected by Trend Micro as the INJECT.IB TROJAN! See here |
 |
rundll32.exe stmctrl.dll, TaskBar |
AdslTaskBar
ISP software, initializes DSL modem |
 |
Remupd.exe |
Agente
Part of Panda Antivirus . Is this an update reminder (guess because of the name), virus definition update reminder or something similar? |
 |
rundll32 amecsa.cpl, RUN_DLL |
AME_CSA
Loads ADSL modem Control Panel applet |
 |
regsvr32.exe ctasio.dll |
AsioReg
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
rregsvr32.exe ctasio.dll |
AsioThk32Reg
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
rundll32.exe [path] ASK.dll rdl |
ASK
Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
reaIplayer.exe |
atidriver
Added by the WARPIGS-E WORM! Note the uppercase "I" in the filename, rather than a lower case "L" |
 |
RunDll32 AudCtrl.dll, RCMonitor |
AudCtrl
Audio control panel? |
 |
RUNDLL32 AUNPS2.DLL, _Run@16 |
AUNPS2
AUNPS adware |
 |
rundll32.exe [path] ToolbarATL.dll, LoadTrayIcon |
Authentic-ID Toolbar
Authentic-ID Toolbar - website authentication utility. Warns you when a site is recognized for phishing or isn't authentic, for example |
 |
REGPROP.EXE WMPADDIN.DLL |
AUTOPROP
Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension |
 |
rundll32 DATADX.DLL,SHStart |
autoupdate
Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "DATADX.DLL" file is found in %System% |
 |
rundll32 SUPDATE.DLL,SHStart |
autoupdate
Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SUPDATE.DLL" file is found in %System% |
 |
rund1132.exe |
Avptask
Added by the AGENT.PKZ TROJAN! |
 |
Rundll32 AXFILTER.DLL, Rundll32 |
AxFilter
?? |
 |
remin.exe |
B.Reader
Birthday Reminder 5.0 - as the name implies |
 |
rundll32 cnbabe.dll, dllstartup |
babeie
CommonName Toolbar spyware. To uninstall see here |
 |
rundll32.exe |
Background Intelligent Transfer Service
Added by the VB-ZD TROJAN! Note - this file is located in the C:Windowshelp folder, and is not to be confused with the legitimate rundll32.exe file! |
 |
rundll32.exe |
BatInfEx
Displays battery status information on an IBM Thinkpad |
 |
rundll32.exe bcmhal9x.dll, bcinit |
BCMHal
BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings |
 |
rundll32.exe [path] NPBelv32.dll, RunDll32_BelNotify |
BelNotify
"BelTech from Belarc enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service" |
 |
Rundll32.exe [path] BDSrHook.dll, Rundll32 |
BIE
BDplugin parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe [path] BatLogEx.DLL, StartBattLog |
BLOG
IBM Thinkpad battery management utility that logs changes in battery conditions such as charging, discharging, etc |
 |
RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent |
BlueToothAuthentication Agent
Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup |
 |
Rundll32 PWRMONIT.DLL, StartPwrMonitor |
BMMGAG
Displays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window |
 |
rundll32.exe [path] BatInfEx.dll, BMMAutonomicMonitor |
BMMMONWND
Battery power management utility for Lenovo (IBM) ThinkPad laptops |
 |
RunDLL32.EXE bs2.dll, DllRun |
BookedSpace
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs2.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe ...Bridge.dll |
Bridge
Flingstone.com browser hijacker |
 |
RakyatKelaparan.exe |
Bron-Spizaetus
Added by the BRONTOK-J or BRONTOK-L WORMS! |
 |
RunDLL32.EXE bs3.dll, DllRun |
Bsx3
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs3.dll" file is located in the Winnt or Windows folder |
 |
RCUI.exe |
BuzMe
Display Client for the BuzMe Internet Call Waiting Service |
 |
RunDLL32.EXE bsx5.dll, DllRun |
bxsx5
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bsx5.dll" file is located in the Winnt or Windows folder |
 |
RunDLL32.EXE bxxs5.dll, dllrun |
bxxs5
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bxxs5.dll" file is located in the Winnt or Windows folder |
 |
REGCNT09.exe |
Card Monitor
For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs |
 |
regedit.exe |
Ccao
Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a "mduu" subfolder, which may change |
 |
rundll32.exe streamci, StreamingDeviceSetup |
Ccdecode
Part of the closed caption decdoder/MS VBI codec. Should only run once |
 |
Rundll32.exe [path] cmail.dll, Rundll32 |
cesmain.dll
CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RunDLL32.EXE cfgmgr51.dll, DllRun |
cfgmgr51
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfgmgr51.dll" file is located in the Winnt or Windows folder |
 |
RunDLL32.EXE cfgmgr52.dll, DllRun |
cfgmgr52
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfgmgr52.dll" file is located in the Winnt or Windows folder |
 |
regload16.exe |
CheckScan32
Added by the AEBOT.K WORM! |
 |
runlli32.exe |
chope
Added by the QQPASS-U TROJAN! |
 |
run_21.exe |
Classes
"Switch" premium rate adult content dialler variant |
 |
rundll.exe setupx.dll, InstallHinfSection ..delwall.inf |
clnwall
?? |
 |
Rundll32 cmicnfg.cpl, CMICtrlWnd |
Cmaudio
System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
 |
RunDll32 CMICNFG3.CPL, CMICtrlWnd |
CmPCIaudio
Registers the Control Panel applet for a C-Media PCI sound card |
 |
Rundll32.exe [path] CNSMIN.DLL, Rundll32 |
CnsMin
CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe [path] AsTsVcc.dll, RegisterModule |
CognizanceTS
Cognizance Corp Identity And Access Management suite |
 |
ribiva.exe |
Comcast Network
Added by a variant of the IRC TROJAN! |
 |
Rundll32.exe SECURE32.CPL, Service |
Compaq Computer Security
?? |
 |
regsvs.exe |
Compatibility Service Process
Added by the GAOBOT.YN WORM! |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
ContentDownload
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe ctrlpan.dll, Restore ControlPanel |
Control
CoolWebSearch Msconfd parasite variant |
 |
rundll32 internat.dll, LoadKeyboardProfile |
ControlPanel
CoolWebSearch parasite variant |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
CoolDownloads
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
CoolMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
razerhid.exe |
Copperhead
Razer Copperhead mouse driver |
 |
Remind32.exe |
Corel Registration
If you don't want to register Corel products and be reminded about it every 2 weeks disable it |
 |
Remind32.exe |
Corel Registration Reminder
If you don't want to register Corel products and be reminded about it every 2 weeks disable it |
 |
rundll32.exe cpu.dll, load |
CPU Watcher
Added by the DLOADER-LO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cpu.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe CrazyTalk.dll, DIIServeMediaFile |
CrazyTalk Serve
CrazyTalk from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS |
 |
rundll32.exe drvmod.dll |
CTDrive
Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvmod.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundIl32.exe |
ctfnom
Added by the LEGMIR-AW TROJAN! |
 |
rundll32.exe dabapi.dll, Rundll32 |
dabrun
SinaUpdateCenter adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dabapi.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Regedit.exe ....data789.tmp |
Data789
Homepage hijacker |
 |
rundll32.exe DeadAIM.ocm, ExportedCheckODLs |
DeadAIM
DeadAIM - feature enhancing product for AOL's Instant Messenger program |
 |
rundll32.exe advpack.dll, DelNodeRunDLL32 submit.exe |
delsubmit
CoolWebSearch parasite variant |
 |
rundll32.exe msconfd.dll, Restore ControlPanel |
Desktop
Added by the BOOKMARKER TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msconfd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
DesktopUpdate
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
READREG |
DevconDefaultDB
Appears to be related to older Creative Soundblaster soundcards |
 |
Root.exe |
DevicePath
Added by the GRUEL WORM! |
 |
regsvr.exe |
DHCP Server
Added by the RBOT-PR WORM! |
 |
rundll32.exe msa32chk.dll |
Dialer
Unidentfied malware |
 |
Rnaap.exe |
DialUp Network Application
Added by a variant of the SDBOT WORM! |
 |
Recalculate.exe |
Diesel
Added by the LAZAR TROJAN! |
 |
regedit /s c:hpdjregfix.reg |
DJREGFIX
DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers |
 |
rundll32 [path] DLBTtime.dll, _RunDLLEntry@16 |
DLBTCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLBUtime.dll, _RunDLLEntry@16 |
DLBUCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLBXtime.dll, _RunDLLEntry@16 |
DLBXCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCCtime.dll, _RunDLLEntry@16 |
DLCCCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll). If you use the 964 printer, Dell recommends leaving dlcctime.dll in place as it fixes compatibility issues on some Dell systems. If you receive an error message on system startup that reads: "Error in C:WINDOWSSystem32spooldriversW32x863DLCCtime.dll Missing entry: RunDLLEntry" Dell offers help here |
 |
rundll32 [path] DLCDtime.dll, _RunDLLEntry@16 |
DLCDCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCFtime.dll, _RunDLLEntry@16 |
DLCFCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCGtime.dll, _RunDLLEntry@16 |
DLCGCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCItime.dll, _RunDLLEntry@16 |
DLCICATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCJtime.dll, _RunDLLEntry@16 |
DLCJCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCQtime.dll, _RunDLLEntry@16 |
DLCQCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] DLCXtime.dll, _RunDLLEntry@16 |
DLCXCATS
Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll dnes.dll, DnDneCheckBindings |
DNE Binding Watchdog
Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work |
 |
rundll dnes.dll, DnDneCheckDUN13 |
DNE DUN Watchdog
Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
DownloadLegalMusic
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
DownloadMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe drkly16j.dll, ServiceCheck |
drkly16j
KidsWatch Time Control parental control software |
 |
rundll32 ..drvupd.inf |
drvupd
Hijacker - drvupd.inf file installs a "searchforge.com" hijack |
 |
rwwnw64d.exe |
DW_Start
Identified as a variant of the AdWare.Win32.ZenoSearch.am malware |
 |
Rcapi.exe |
ElsaCapiCtl
Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem |
 |
reg32.exe |
EReg
EReg is a software registration tool incorporated on products such as those by Br?derbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it |
 |
realmon.exe |
eTrust Realtime Monitor
Added by the LAZAR.B TROJAN! |
 |
Rundll32.exe [path] cdnspie.dll, ExecFilter |
ExFilter
CNNIC Update pest |
 |
RMSysTry.exe |
Extender Resource Monitor
Related to Windows Media Center from Microsoft |
 |
runfc.exe |
fc
Added by the CAMPURF WORM! |
 |
R3proxy.exe |
Fellowes Proxy
Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice |
 |
rnd32.exe |
file laoder configuration
Added by the RBOT.BQJ WORM! |
 |
rundll32.exe QaBar.dll, ForceShowBar |
ForceShow
AdultLinks.QBar parasite related! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "QaBar.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
FreeMP3download
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe fstsvc.dll,start |
fstsvc
Added by the AKBOT-AA WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fstsvc.dll" file is found in %System% |
 |
rundll32.exe ftutil2.dll, SetWriteCacheMode |
ftutil2
Related to Promise Technology's FastTrak SX4030/4060 PCI ATA Raid 5 controller (and possibly others) |
 |
ra32.exe |
f~a
Added by the CAY TROJAN! |
 |
rundll32.exe [path] tbGame.dll, DllShowTB |
Games toolbar
Topconverting.com180Search "Games Toolbar" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
realsched.exe |
gcasServ
Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
 |
rundll32.exe gddlib.dll,start |
Gddlib
Added by the AKBOT.EG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gddlib.dll" file is found in %System% |
 |
regsvc32.exe |
Generic Service Process
Added by the GAOBOT.UJ or GAOBOT.UL WORMS! |
 |
regsvc32.exe |
Generic Services Process
Added by the GAOBOT.SY WORM! |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
GetMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
GetTheMusic
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32 ctccw32.dll, findwnd |
gfxtray
Detected by Kaspersky as the AGENT.AOU TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
readme.exe |
gouday.exe
Added by the BEAGLE.C WORM! |
 |
rundll32 gspndll.dll, postInstall final |
GsiFinal
USB DSL modem related - [what does it do and is it required in startup? |
 |
rundll32 ...gvagfxj.dll |
gvagfxj
Unidentified adware, spyware or virus |
 |
rundll32.exe he3bbcff.dll, EnableRunDLL32 |
he3bbcff
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "he3bbcff.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe he3e3fc4.dll, EnableRunDLL32 |
he3e3fc4
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "he3e3fc4.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe [path] helper.dll |
helper.dll
CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Remind32.exe |
Hewlett Packard Recorder
HP multifunction registration |
 |
rnxntup.exe |
hhtnsn
Added by a variant of the ORCU.B TROJAN! |
 |
raidman.exe |
HighPoint ATA RAID Management Software
HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID |
 |
runlli32.exe |
HKEYok
Added by the QQPASS-U TROJAN! |
 |
remote.cmd |
hotdlll
Added by the BANKER-EHG TROJAN! |
 |
Remind32.exe |
HP-Aio Flight
HP multifunction registration |
 |
regsvr32.exe ....HREF.OCX |
HREF.OCX
HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller |
 |
rundll32.exe icdd7ee6.dll, EnableRunDLL32 |
icdd7ee6
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icdd7ee6.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe icddefff.dll, EnableRunDLL32 |
icddefff
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icddefff.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe Icsdclt.dll, ICSClient |
ICSDCLT
Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines |
 |
rundll32.exe [path] tbextn.dll DllShowTB |
IE Menu Extension toolbar
Topconverting.com180Search "IEMenuExtension" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe iel2cde8.dll, EnableRunDLL32 |
iel2cde8
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "iel2cde8.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe ielcaabe.dll, EnableRunDLL32 |
ielcaabe
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ielcaabe.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe [path] IKL.dll |
IKL
IKL surveillance software. Uninstall this software unless you put it there yourself |
 |
rundll32 image.dll, Install |
Image
CoolWebSearch parasite variant |
 |
rundll32.exe ********.dll, realset [* = random char] |
InfoData
Added by the VUNDO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe EGDHTML_1023.dll, InstantAccess |
Instant Access
InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe eg_auth_****.dll, InstantAccess [**** = digits] |
Instant Access
InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe EGCOMLIB_****.dll, InstantAccess [**** = digits] |
Instant Access
InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe EGCOMSERVICE_****.dll, InstantAccess [**** = digits] |
Instant Access
InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe p2esocks_****.dll, InstantAccess [**** = digits] |
Instant Access
InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
reminder.exe |
Instant Update Center
From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG. PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner |
 |
regedit.exe /s %windir%c:[month number] |
Internal
Added by the FORTNIGHT.D TROJAN! |
 |
recruit.exe |
Internet
Added by the RBOT-AJG WORM! |
 |
regsvr32.exe Ir41_32.ax |
Ir41_32.ax
Intel® Indeo® video 4.4 Decompression Filter related. The "Ir41_32.ax" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe iSecurity.cpl, SecurityMonitor |
iSecurity applet
Detected by Trend Micro as the DLOADER.UZO TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
remote.cmd |
java
Added by the BANKER-EHG TROJAN! |
 |
runjava.exe |
Java Runtime Value
Added by the RBOT-DDJ WORM! |
 |
Reminder.exe |
Kana Reminder
Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time |
 |
regsvr32 kdp****.dll [* = random char] |
Kazaa Download Accelerator Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe apphelp.dll, ShimFlushCache |
KB926239
Microsoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer |
 |
rundll32 kctl32.dll, initialize |
kernctl32
Added by the AGENT.AT TROJAN! |
 |
Rlid.exe |
Key1
Added by the LIXY TROJAN! |
 |
rundll32 setupapi, InstallHinfSection... keymgr3.inf |
keymgrldr
CoolWebSearch Oemsyspnp parasite variant |
 |
rnnypbw.exe |
Kgjg
Added by the QuickLinks/Forethought adware |
 |
run32dll.exe |
klp
PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online |
 |
razerhid.exe |
Krait
Razer Krait mouse driver |
 |
regsvr32.exe kvern16.dll |
kvern16.dll
DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "kvern16.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe kw3eef76.dll, EnableRunDLL32 |
kw3eef76
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kw3eef76.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
razerhid.exe |
Lachesis
Razer Lachesis mouse driver |
 |
RePEAtLD.exe |
LAsIAf32
Added by the REPEATLD WORM! |
 |
relaunch.exe |
Launcher
Audio Applications Launcher for the Philips Rythmic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs |
 |
rundll32.exe ..lhttseng.inf, RemoveCabinet |
lhttseng
Left over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine |
 |
rundll32.exe li01f948.dll, EnableRunDLL32 |
li01f948
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "li01f948.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe libtec.dll,start |
libtec
Added by the AKBOT-AI WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "libtec.dll" file is found in %System% |
 |
runservice.exe |
LicCrtl
Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program |
 |
rundll32.exe MMFS.DLL, Service |
LicCtrl
Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program. Note that the "MMFS.DLL" file is located in the Winnt or Windows folder |
 |
Rubicon.exe |
LIU
Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway |
 |
rundll32.exe |
Ljx
Added by the LINEAG-ABD TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in the "inf" sub-folder |
 |
rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF |
LLMODCL2
?? |
 |
rundll32.exe |
load
Added by the WOWCRAFT TROJAN! |
 |
rundl132.exe |
load
Added by the LOOKED-CK WORM! |
 |
rundll32.exe mshtmpre.dll, MShtmpre |
LoadHTML
Mshtmpre adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mshtmpre.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe |
loadMecq3
Added by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in the Root folder (C:), (D:), etc |
 |
rundll32.exe |
loadMefs
Added by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in the Windowsinf or Winntinf folder |
 |
Rundll32.exe powrprof.dll |
LoadPowerProfile
Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings |
 |
Rundll.exe powerprof.dll |
LoadPowerProfile
Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe" |
 |
rundl.exe |
LoadPowerProfile
Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll |
 |
Rundll32.exe |
LoadPowerProfile
Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line |
 |
rundll32.exe powerprof.dll CheckPowerProfile |
LoadPowerScheme
Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rest In Peace |
LoadService
Added by the KANGAROO-A WORM! |
 |
rundll32.exe SIPSPI32.dll, SIPSPI32 |
LoadSIPS
123Mania adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SIPSPI32.dll" file is found in the System folder |
 |
ragui.exe |
LogMeIn GUI
RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone |
 |
Rundll32.exe rgtndz.dll |
logonUiInit
Identified as a variant of the Trojan-Clicker.Win32.Agent.bqy malware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rgtndz.dll" file is found in %System% |
 |
RundlI.exe |
LTM2
Added by the MULTIDRP.BG TROJAN! |
 |
rundll32.exe ltssvc.dll,start |
ltssvc
Added by the AKBOT-AG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ltssvc.dll" file is found in %System% |
 |
rundll32.exe |
LTT2
Added by the LINEAGE-BI TROJAN! |
 |
rundll32 [path] LXBStime.dll, _RunDLLEntry@16 |
LXBSCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXBTtime.dll, _RunDLLEntry@16 |
LXBTCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXBUtime.dll, _RunDLLEntry@16 |
LXBUCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXBXtime.dll, _RunDLLEntry@16 |
LXBXCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXBYtime.dll, _RunDLLEntry@16 |
LXBYCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCCtime.dll, _RunDLLEntry@16 |
LXCCCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCDtime.dll, _RunDLLEntry@16 |
LXCDCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCEtime.dll, _RunDLLEntry@16 |
LXCECATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCFtime.dll, _RunDLLEntry@16 |
LXCFCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCGtime.dll, _RunDLLEntry@16 |
LXCGCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCJtime.dll, _RunDLLEntry@16 |
LXCJCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCQtime.dll, _RunDLLEntry@16 |
LXCQCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCRtime.dll, _RunDLLEntry@16 |
LXCRCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCTtime.dll, _RunDLLEntry@16 |
LXCTCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXCYtime.dll, _RunDLLEntry@16 |
LXCYCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXDCtime.dll, _RunDLLEntry@16 |
LXDCCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details |
 |
rundll32 [path] LXDItime.dll, _RunDLLEntry@16 |
LXDICATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rundll32 [path] LXDJtime.dll, _RunDLLEntry@16 |
LXDJCATS
Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) |
 |
rarww.exe |
Macromedia Critical Updater
Added by a variant of the RBOT WORM! |
 |
RESWIN.EXE |
Mania Win Restore
Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs |
 |
rundll32.exe MSDServ.dll, check registry |
Mass storage check registry
Used with a USB based smartmedia card reader |
 |
Rundll32 CTMBHA.DLL, MBMon |
MBMon
Creative Filter AudioControlMB Module - related to the Creative Audigy line of sound cards. What does it do and is it required? |
 |
RuLaunch.exe |
McAfee.InstantUpdate.Monitor
Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
 |
runonce.exe |
mdac_runonce
Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". |
 |
Root.exe |
MediaPath
Added by the GRUEL WORM! |
 |
reloc32.exe |
Memory relocation service
Added by the RELFEERWORM! |
 |
runservice.exe |
Micosoft Data Core
Added by the IRCBOT.BK WORM! |
 |
radnom.exe |
Microsoft
Added by the RBOT-GHO WORM! |
 |
rtvcscan.exe |
Microsoft
Added by the RBOT-GGU WORM! |
 |
rundll.exe |
Microsoft
Added by the RBOT-GSJ WORM! |
 |
rundll32.exe |
Microsoft (R) Windows DLL Loader
Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in a "dll" subfolder of the Winnt or Windows folder |
 |
rasmngr.exe |
Microsoft DirectX
Added by a variant of the RBOT WORM! |
 |
runapidll.exe |
Microsoft Dll
Added by the RBOT-GRG WORM! |
 |
rundll64 |
Microsoft Install Shield Services
Added by the RBOT-FSH WORM! |
 |
Rhost32.exe |
Microsoft IT Update
Added by a variant of the IRCBOT TROJAN! |
 |
regedit.exe |
Microsoft Regestry Edit Manager
Detected by Trend Micro as the SHEUR.HC WORM! See here |
 |
regedit32.exe |
Microsoft Regestry Manager
Added by a variant of the IRCBOT.ARD WORM! |
 |
registry32.exe |
Microsoft Regestry Manager
Added by the IRCBOT.ARD WORM! |
 |
router.exe |
Microsoft Router Manager
Added by a variant of the IRCBOT TROJAN! |
 |
rserv.exe |
Microsoft Server
Added by the AGOBOT.AVS WORM! |
 |
rundll.exe |
Microsoft Service
Added by the POPO-A WORM! Note - this is NOT the Windows system file of the same name as described here |
 |
reg32.exe |
Microsoft System Firewall 2006.2
Added by a variant of the SDBOT WORM! |
 |
rundll32.dll |
Microsoft Update
Detected by Kaspersky as the CIADOOR.GN BACKDOOR! See here |
 |
rundll32.exe |
Microsoft Update 32
Detected by Kaspersky as the RBOT.AIE BACKDOOR! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rxxhost.exe |
Microsoft Update DLL
Added by a variant of the RBOT WORM! |
 |
rxxhost.exe |
Microsoft Update Machine
Added by the RBOT.EP WORM! |
 |
rxhost.exe |
Microsoft Update Machine
Added by the RBOT.FC WORM! |
 |
rundll24.exe |
Microsoft Update Module
Added by the RBOT-PS WORM! |
 |
rpcxWindows.exe |
Microsoft Windows Secure Server
Added by the RBOT-LL WORM! |
 |
rpcxwinupdt.exe |
Microsoft Windows Secure Update
Added by an unidentified WORM or TROJAN! |
 |
rundlls.exe |
Microsoft Windows Update
Added by the HABRACK WORM! |
 |
rhost32.exe |
Microsoft Windows Update
Added by a variant of the IRCBOT TROJAN! |
 |
RunDLL32.exe ehuihlp.dll, BootMediaCenter |
Microsoft® Windows® Operating System
Starts Windows Media Center every time Windows Vista (Home Premium or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center -> Tasks -> Settings -> General -> Startup and Window Behaviour |
 |
rundll32.exe oobefldr.dll, ShowWelcomeCenter |
Microsoft® Windows® Operating System
Shows the Welcome Center every time you boot into Windows Vista |
 |
rune.pif |
Microsoftf DDEs ContDLL
Added by the RBOT-AGF WORM! |
 |
runm.pif |
Microsoftf DDEs ContrDL
Added by the RBOT-AFQ WORM! |
 |
RBuilder.exe |
MicrosoftUpdate
Added by the DLOADR-BMV TROJAN! |
 |
read.pif |
Microsoftz turn Control
Added by the RBOT-AFS WORM! |
 |
rundll32.exe migrate.dll, CallVendorSetupDlls |
MigrationVendorSetupCaller
?? |
 |
rundllc32b.exe |
Mircrosoft Windows Config DLL
Added by the RBOT-ZY WORM! |
 |
recover.exe |
mmsys
?? |
 |
RunDll32 |
MMSystem
Added by the FUNNER-A WORM! |
 |
readernotify.exe |
Mobipocket Reader Notifications
Part of Mobipocket Reader - "Store all your eBooks, eNews & self-published eDocs on your PC. Download eBooks in Mobi format from your favorite ebookstores to read on your smartphone, PDA, laptop or on your desktop PC" |
 |
RUNDLL32.EXE reg.dll, ondll_reg |
Module Call initialize
Added by the LOVGATE.C WORM! |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
MoreContent
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
MP3Collection
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
MP3download
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
MP3freeDownload
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
RealPlyr.exe |
MS Real Player
Added by the RBOT.MR WORM! |
 |
rundll32.exe wincheck071008.dll mymain |
mscheck
Detected by Trend Micro as the AGENT.ADXH TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincheck071008.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RUNDLL64.dll.vbs |
MSConfigs
Added by the WEKODE-B WORM! |
 |
rundll32.exe drvkoc.dll |
MSDrive
Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvkoc.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe drvmod.dll |
MSDrive
Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvmod.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe drvsoh.dll |
MSDrive
Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drvsoh.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
r3grun.exe |
MSFTP Service Config
Added by a variant of the SDBOT WORM! |
 |
RealOneMessageCenter.exe |
MsgCenterExe
RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way |
 |
rtkmsg.exe |
msMGR
Added by the SDBOT-BPY WORM! |
 |
regsvr32 /s mqrt.dll |
MsmqIntCert
Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? |
 |
Reosmsngr.exe |
MSN Messenger
Added by a variant of the SPYBOT WORM! |
 |
raloded.exe |
Msn Service
Added by the MYTOB-DY WORM! |
 |
regsvc32.exe |
MSRegSvc
Homepage hijacker that changes your homepage to an adult content site |
 |
realsched.exe |
MSService_v1.0
EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
 |
run dll.exe |
MSTask
Yuupsearch adware |
 |
rpcxctx.exe |
MSVsmt
Added by an unidentified WORM or TROJAN! |
 |
recsl.exe |
mysvcig38
Added by a variant of the RBOT-FOU WORM! |
 |
rundll32 [path] M3PLUGIN.DLL,UPF |
MyWebSearch Plugin
MyWebSearch parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RuxDLL32.exe |
NAV
Added by the MAPSON.D WORM! |
 |
rundll32.exe navupd.dll, Startup |
NAVUpd
Added by the NAVU TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
regedit.exe |
NeroCheck
Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD/DVD burning program. Also, it is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
recall.exe |
netservices
Added by the WOOTBOT.D WORM! |
 |
rsvc32.exe |
Network Administration Service
Added by the RBOT.ABH WORM! |
 |
rundll32 [path] NEWDOT~1.DLL, ClientStartup |
New.net Startup
NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32 [path] NEWDOT~1.DLL, NewDotNetStartup |
New.net Startup
NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32 [path] NEWDOT~2.DLL, ClientStartup |
New.net Startup
NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32 [path] NEWDOT~2.DLL, NewDotNetStartup |
New.net Startup
NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
NiceDownloads
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
NiceMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
regedt32.exe |
NOD32 FiX
NodFix is a is a potentially unwanted application. This application is given an (X) status because we does not and will not support Cracks or Warez. Do not delete the regedt32.exe as it is the legitimate Windows application. NodFix interferes with the default settings of the NOD32 AV application allowing to bypass its free using period as well as changes the default update server to that eval signatures thus allowing to update NOD32 without password. Note - to avoid interfering with the NOD32 application original settings no full cleanup can be provided |
 |
rundll32.com |
NT security
Added by the RBOT-AJC WORM! |
 |
RPS.exe |
ntl Netguard
ntl Netguard - anti-virus a package of services, specifically designed to keep you safe and secure with their ntlworld online services |
 |
rundll32 [path] RyDial.dll, QuickStart |
ntlfreedom
NTL Freedom dial-up ISP software - not required |
 |
rundll32 nvclock.dll, fnNvclock |
NVCLOCK
Overclocking utility for nVidia based graphics cards? |
 |
rundll32.exe NvQtwk.dll, NvColorInit |
NvColorInit
Associated with Nvidia based graphics cards |
 |
rundll32.exe NvCpl.dll, NvStartup |
NvCpl
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card |
 |
rundl32.exe |
NvCpl
Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as "rundll32.exe NvCpl.dll,NvStartup" |
 |
rundll32.exe NvQtwk.dll, NvCplDaemon |
NvCplDaemon
System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here) |
 |
rundll32.exe NvCpl.dll, NvStartup |
NvCplDaemon
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card |
 |
rundll32.exe nvHotkey.dll |
NVHotkey
Enables the use of "hot keys" for changing setting on Nvidia graphics |
 |
rundll32.exe NvQtwk.dll, NvTaskbarInit |
NvidiaQuickTweak
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
 |
rundll32.exe nview.dll, nViewLoadHook |
NVIEW
This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers |
 |
rundll32.exe NvQtwk.dll, NvXTInit |
NvInitialize
Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled |
 |
RUNDLL32.EXE ...NVMCTRAY.DLL, NvTaskbarInit |
NVMCTRAY
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
 |
RunDLL32.exe NvMCTray.dll, NvTaskbarInit |
NvMediaCenter
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
 |
rundll32.exe NvQtwk.dll, NvTaskbarInit |
NVQuickTweak
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
 |
rundll32.exe nvsvc.dll, nvsvcStart |
NvSvc
Related to NVIDIA graphics cards |
 |
rundll32.exe nxgsvc.dll,start |
nxgsvc
Added by the AKBOT.BA WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "nxgsvc.dll" file is found in %System% |
 |
rundll32.exe nxosys.dll,start |
nxosys
Added by the AKBOT.BD WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "nxosys.dll" file is found in %System% |
 |
Rundll32.exe OFUSBS.DLL, WatchForConnection OfotoNow |
OfotoNow USB Detection
Autodetects when a digital camera is attached to a USB port and launches OfotoNow image software. Available via Start -> Programs |
 |
runoledb32.exe |
OLEDb Service
Added by a variant of the SPYRE.B TROJAN! |
 |
RunDLL32.EXE oo4.dll, DllRun |
oo4
BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "oo4.dll" file is located in the Winnt or Windows folder |
 |
runme.exe |
Open2Enter
Adult content dialler |
 |
runme2.exe |
Open2Enter
Adult content dialler |
 |
regedit.exe /s ...rad03FA6.tmp |
OPQFile
Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit |
 |
RAGE128TWEAK.EXE |
OrigRage128Tweaker
Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com |
 |
rk.exe |
OSS
MarketScore parasite - ActiveX control used to download premium-rate dialers |
 |
rlvknlg.exe |
OSS
MarketScore parasite - ActiveX control used to download premium-rate dialers |
 |
rrup.exe |
Osus
PurityScan/Clickspring adware. The executable is located in the user's "Application Data" folder or the Program Fileshtwu folder |
 |
Rundll32 P17.dll, P17Helper |
P17Helper
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
Rundll32 SPIRun.dll, RunDLLEntry |
P17Helper
Related to Creative audio products. What does it do and is it required? |
 |
register.exe |
palmOne Registration
Registration reminder for Palm products |
 |
runppdrv.exe |
Paperport
Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here |
 |
Reminder.exe |
PC Pitstop Optimize Reminder
Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2 |
 |
realtime.exe |
PCDRealtime
Apparently the monitoring device for PC Doctor Online. It provides a "free" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to "order" the fee-based fixes from its web site |
 |
RunProfiler.exe |
PCDrProfiler
Part of PC Doctor software installed for some machines. Disabling or enabling it is down to your preference |
 |
regsvr32 sfg_****.dll [* = random char] |
PCShield
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
remoterm.exe |
PCTVRemote
Controls the remote control on some Pinnacle TV tuners |
 |
RegistryController.exe |
PDF Converter Registry Controller
Nuance (was Scansoft) PDF Converter Registry Controller related - what does it do and is it required? |
 |
Residence.exe |
Picture Package VCD Maker
Sony Picture Package software for their range of Digital Handycam video cameras. Used to connect the camcorder via USB and allows the user to burn the content directly to a CD |
 |
Reminder.exe |
PitFrame Module
Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2 |
 |
regsvr32 veev****.dll [* = random char] |
Popup Blocker Updater
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
regsvr32 pdfupd.dll |
Popup Defence Updater
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "pdfupd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Rundll32.exe atgban.dll |
PostSetupCheck
AdRotator adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "atgban.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Rundll32.exe gzmrt.dll |
PostSetupCheck
AdRotator adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gzmrt.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Rundlll.exe |
PowerManagement
Added by the SURDUX TROJAN! |
 |
rundl132 kenel.dll, PowerProfileEnable |
PowerPrifile
Added by the INMOTA WORM! |
 |
Regedit.exe /s ...PowerSet_8100_CU.REG |
PowerSet
Appears to be Toshiba power management related |
 |
RUNXMLPL.exe |
preload
Software found on Acer computers from Wistron. Information suggests it maps keyboard buttons to operating system functions |
 |
RUNDLL32.EXE MSSIGN30.DLL ondll_reg |
Protected Storage
Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe ptipbmf.dll, SetWriteCacheMode |
Ptipbmf
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
 |
Rundll32.exe ptipbm.dll, SetWriteBack |
PtiuPbmd
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller |
 |
rundll32.exe ptmg1v.dll, DllRunMain |
PTRGMYGK
Added by an unidentified TROJAN, WORM or other malware! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32 PwrMonit.dll |
Pwrmonit
IBM's proprietary 'battery maximiser' and power monitoring software for laptops |
 |
rundll32.exe qkoszvd.dll, jwezubg |
qkoszvd.dll
Added by the DLOADR-AVD TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qkoszvd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
ru.exe |
Quicktlme
Adult content dialler |
 |
rundll32.exe msprt.dll |
R
Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rabbit.exe |
RabbitWannaHome
Added by the MIMAIL.S WORM! |
 |
RaboSessionMon.exe |
Rabo Session Monitor
Related to RaboBank electronic banking software |
 |
RaConfig2500.exe |
RaConfig2500
RaLink wireless LAN configuration utility |
 |
RadarSync.exe |
RadarSync
Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically |
 |
RadBoot.exe |
RadBoot
RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings |
 |
Radio365TrayAgent.exe |
Radio365Agent
Radio365 - create playlists and broadcast live straight from your PC! |
 |
RadioSvr.EXE |
RadioSvr
Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
 |
raid_tool.exe |
RaidTool
VIA V-RAID Tool - hard disk striping/mirroring utility for increased performance and reliability |
 |
Rainlendar.exe |
Rainlendar
Rainlendar is a customizable calendar that displays the current month |
 |
Rainlendar2.exe |
Rainlendar2
Rainlendar is a customizable calendar that displays the current month |
 |
Rainmeter.exe |
Rainmeter
Rainmeter is a customizable performance meter, which can display the CPU load, memory utilization, etc |
 |
RAM_XP.exe |
RAM Idle Professional
RAM Idle LE - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
RAMASST.exe |
RAMASST
Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs |
 |
rb.exe |
RamBooster2
Added by the AKAK TROJAN! |
 |
ramdef.exe |
RAMDef
Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
RDTask.exe |
RAMDrive
Virtual Hard Drive (Ram Drive) from Farstone - takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive |
 |
ramidle.exe |
RamIdle
RAM Idle LE - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
RAMpage.exe |
RAMpage
Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source |
 |
random.exe |
random
Added by the DLOADER-KM TROJAN! |
 |
rst.exe |
Random Interface Network
Added by the DELBOT-P WORM! |
 |
rinsv.exe |
Random Interface Network Manager
Added by the DELBOT-L WORM! |
 |
rant.exe |
rant
Added by the RBOT-ZB WORM! |
 |
RAPAPP.EXE |
RapApp
Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch |
 |
ravsecs.exe |
Rapdata
Added by the QQPASS-V TROJAN! |
 |
rabseuser.exe |
Rapdatae
Added by the QQPASS-S TROJAN! |
 |
ravseteyns.exe |
Rapdatybs
Added by the PWS-ACP TROJAN! |
 |
rrpcsb.exe |
Rapid Restore
XPoint "Rapid Restore PC" - a "Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" |
 |
rb32.exe |
RapidBlaster
RapidBlaster parasite. Recommended you use RapidBlaster Killer to uninstall - see here |
 |
ravspeger.exe |
Raptelnet
Added by the QQPASS-AA TROJAN! |
 |
ravspegtl.exe |
Raptelt
Added by the QQPASS-AB TROJAN! |
 |
rasmngr.exe |
RasCon Remote Access Service Manager
Added by the SPYBOT.EM WORM! |
 |
rasctrs.exe |
rasctrs
Hijacker, also detected as the ADWAHECK TROJAN! |
 |
rasman32.exe |
rasman
Added by the BCKDR-QGN TROJAN! |
 |
RasMan.exe |
RasMan.exe
Added by the FEUTEL-H TROJAN! |
 |
ravtray8.exe |
RAV8Tray
RAV anti-virus related |
 |
RavMon.exe |
RavAv
Added by the BDOOR-DIJ TROJAN! Note - this file is located in the %WinDir% directory, and must NOT be confused with the legitimate RAV antivirus file of the same name! |
 |
RavMonE.exe |
RavAv
Added by the RJUMPF-F WORM! |
 |
RAVEN_VLZS.EXE |
RAVEN_VLZS.EXE
DownloadReceiver parasite - no longer in existence |
 |
RavMon.exe |
RavMon
RAV AntiVirus |
 |
rund1132.exe |
Ravshell
Added by the AGENT.OKZ TROJAN! |
 |
ravstub.exe |
RavStub
Rising antivirus |
 |
rund1132.exe |
ravtask
Added by the DLOADER.IYT TROJAN! |
 |
RavTask.exe |
RavTask
Rising antivirus |
 |
RavTimer.exe |
RavTimer
RAV AntiVirus |
 |
ravsesur.exe |
RavUptpe
Added by the QQPASS-T TROJAN! |
 |
rav_temp.exe |
rav_temp.exe
?? |
 |
razerhid.exe |
razer
Razer mouse driver |
 |
rb32.exe |
rb32 lptt01
RapidBlaster variant (in a "RapidBlaster" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
rb32.exe |
rb32 ml097e
RapidBlaster variant (in a "RapidBlaster" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
rbenh.exe |
rbenh ml***e
RapidBlaster variant (in a "RBEnhance" folder in Program Files) where *** represents random digits. Recommended you use RapidBlaster Killer to uninstall - see here |
 |
rcf.exe |
Rcf Driver
Added by the RANDEX.BLD WORM! |
 |
rcimlby.exe |
rcimlby.exe
Added by the SDBOT-DHK WORM! |
 |
rcron.exe |
rCron
"Switch" premium rate adult content dialler variant |
 |
RCSCHED.EXE |
RCScheduleCheck
Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running" |
 |
RCSync.exe |
RCSync
PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
 |
RDCLIENT.EXE |
RDClient
Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection |
 |
RunDll16.exe |
RDLL
Added by the SDBOT.F TROJAN! |
 |
rundll32.exe readdb40.dll, EnableRunDLL32 |
readdb40
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "readdb40.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
readericon45G.exe |
readericon
Tray icon to set various configuration settings for Sunkist (and maybe other) media card readers |
 |
realjbox.exe |
REAL
Real Jukebox - MP3 and music files player |
 |
Reaiplay.exe |
Real Internet Player
Added by a variant of the SPYBOT WORM! |
 |
realplayer2.exe |
Real Media Player
Added by a variant of the RBOT WORM! |
 |
realupd.exe |
Real player updater
Added by the PARLAY TROJAN! |
 |
RealAudio.exe |
real scheduler.hta
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
 |
Real-Tens.exe |
Real-Tens
DownloadWare adware |
 |
RealAudio.exe |
RealAudio
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
 |
realaudio32.exe |
Realaudio Player
Added by the AGOBOT.AFR WORM! |
 |
RealPlay.exe |
RealDownload
Download manager. Available via Start -> Programs |
 |
RFTRay.exe |
Reality Fusion GameCam SE
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
 |
realplay.exe |
realplay
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
 |
realplay.exe |
realplay lptt01
RapidBlaster variant (in a "RealPlay" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name |
 |
realplay.exe |
realplay ml097e
RapidBlaster variant (in a "RealPlay" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name |
 |
realplay.exe |
RealPlayer
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
 |
rnathchk.exe |
RealPlayer Ath Check
Added by the MYTOB.AG WORM! |
 |
realsched.exe |
Realplayer Codec Support
Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
 |
realplay.exe |
Realplayer One
Added by the RBOT-NK WORM! |
 |
RealPlay.exe |
Realplayer Video
Added by a variant of the RBOT WORM! |
 |
Realplayer.exe |
Realplayer.exe
Added by the DELF.CNV TROJAN! |
 |
realupd32.exe |
RealPlayerUpdater
Added by the LOHAV-T TROJAN! |
 |
Realpopup.exe |
Realpopup
RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" |
 |
realsched.exe |
Realsched
Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
 |
RealSPEED.Exe |
RealSPEED
RealSPEED - tweaking utility to speed-up your internet connection |
 |
realmon.exe |
Realtime Monitor
Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates |
 |
RealTimeUpdate.exe |
RealTimeUpdate
Product description in properties is "InternetExplorerCommunicationAgent Module" ? |
 |
realsched.exe |
realtpsk
Chinese originated adware - detected by Panda antivirus as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
 |
RealPlay.exe |
RealTray
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
 |
realupd.exe |
RealUpdater
Added by the PARLAY or MITGLIEDER.I TROJANS! |
 |
RebateNation0.exe |
RebateNation0
RebateNation adware |
 |
Reboot.exe |
Reboot
MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards |
 |
recguard.exe |
Recguard
On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
 |
reclip.exe |
Reclip
Reclip Popup Clipboard manager |
 |
RH.DLL |
Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}
SmartPops search hijacker |
 |
Rundll.exe |
recover.bmp.exe
Added by the ANAFTP-01 TROJAN! Note - this is NOT the Windows system file of the same name as described here |
 |
RECOVE~1.EXE |
RecoverFromReboo
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RecoverFromReboot.exe |
RecoverFromReboo
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RECOVE~1.EXE |
RecoverFromReboot
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RecoverFromReboot.exe |
RecoverFromReboot
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RecSche.exe |
RecShe
Recording scheduler for WatchTV Capture Card (TV Tuner card) |
 |
recycler.exe |
Recycle Bin Handler
Added by the SHUCKBOT-A TROJAN! |
 |
recyclecl.exe |
Recycler DO NOT MODIFY
Added by the RBOT.DDA WORM! |
 |
redflag.exe |
Red Flag
PMS prediction program with modes for guys and girls - no longer available |
 |
RSEDNClient.exe |
Red Swoosh EDN Client
Red_Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other, rather than from webservers |
 |
redirect*.exe |
redirect
Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit |
 |
reek32.exe |
Reek 32 Server
Added by the RANDEX.AL WORM! |
 |
referee.exe |
Referee
MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
 |
ReflexVision.exe |
Reflex Vision
Reflex Vision from Increment Software. "A background application for Windows XP that makes switching windows faster and easier" |
 |
Refresh.exe |
Refresh
(Iomega) Refresh - loads the Iomega desktop icons at startup |
 |
Reg.hta |
Reg
Passon homepage hi-jacker |
 |
REGSRV32.EXE |
Reg Service
Added by the RBOT.ZW WORM! |
 |
Reg32.exe |
Reg32
Hijacker - redirecting to only-virgins.com |
 |
reg32.exe |
reg32
Added by the NOUPDATE.B TROJAN! |
 |
reg33.exe |
Reg32
CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN! |
 |
RCHelper.exe |
RegClean Expert Scheduler
"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" |
 |
RCScheduler.exe |
RegClean Expert Scheduler
"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" |
 |
Regcpm32.exe |
RegCompres
Added by the POLDO.B TROJAN! |
 |
REGCPM32.EXE |
RegCompres
Added by the DASMIN-E TROJAN! |
 |
REGCXDINAF.EXE |
Regcxdinaf
Added by the BANCOS-BW TROJAN! |
 |
REGCXMARQ.EXE |
Regcxmarq
Added by the BANCOS.DK TROJAN! Note that the filename has a leading space, ie, " REGCXMARQ.EXE" |
 |
Regcxn.exe |
Regcxn
Added by the COIBOA-D TROJAN! |
 |
regdefend.exe |
regdefend
"RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage" |
 |
regedit.exe |
regedit
Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Regsrv32.com |
REGEDIT
Added by the SOUTHGHOST WORM! |
 |
regedit.exe |
regedit
Added by the GANBATE.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a "securityDatabase" subfolder |
 |
RegEdit32.exe |
RegEdit32
Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder |
 |
runlli32.exe |
Regexit
Added by the QQPASS-U TROJAN! |
 |
regfreeze.exe |
RegFreeze
RegFreeze anti-spyware software |
 |
reginfo32.exe |
reginfo32
?? |
 |
RegistryManage.exe |
Register Manager
Added by the SDBOT.AYH WORM! |
 |
register.exe |
Register MediaRing Talk
If you don't want to register MediaRing and be reminded about it every bootup disable it |
 |
regsvr32.exe ..csseqchk.dll |
Register SeqChk
?? |
 |
REGIST~1.EXE |
RegisterDropHandler
Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
 |
RegTool.exe |
Registration-Studio 8
Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems |
 |
Regrun.exe |
Registry Checker
Added by the SDBOT TROJAN! |
 |
Regclean.exe |
Registry Cleaner
Registry Cleaner misleading security software - not recommended, see here |
 |
regintmon.exe |
Registry Integrity Checker
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
regloadr.exe |
Registry Loader
Added by the GAOBOT.AO WORM! |
 |
regmon.exe |
Registry Monitor
Added by the QKH TROJAN! |
 |
regprotect.exe |
Registry Protector
Added by the ARIVER.A WORM! |
 |
regscanr.exe |
Registry Scanner
Added by a variant of the OPTIX TROJAN! |
 |
regsvr.exe |
Registry Serv
Added by the WEBMONEY-G TROJAN! |
 |
regsrv32.exe |
Registry Server
Added by the RBOT-GM WORM! |
 |
regserv.exe |
Registry Server
Added by a variant of the IRCBOT TROJAN! See here |
 |
REGSRV32.EXE |
Registry Service
Added by a variant of the RBOT WORM! |
 |
resvs.exe |
Registry Service
Added by the DELBOT-I WORM! |
 |
Registry.exe |
Registry Services
Added by the CILE TROJAN! |
 |
Regsys.exe |
Registry System
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
roses.exe |
Registry Value Name
Added by the RBOT-AFT WORM! |
 |
rundll32.exe chkreg.dll, CheckRegistry |
RegistryCheck
Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
registrycleanfix.exe |
RegistryCleanFixMFC
RegistryCleanFix misleading security program - not recommended, see here |
 |
RegMech.exe |
RegistryMechanic
Registry Mechanic - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages" |
 |
registry.pif |
RegistryMonitor
Affilred adware |
 |
REGIST~1.EXE |
REGIST~1
Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
 |
RegKillTray.exe |
RegKillTray
DVD region killer part of CloneDVD from Elaborate Bytes AG. Copies the main movie, Special Features and/or the original menu onto a DVD Recordable or onto your harddisk |
 |
regmaping.exe |
Regmonitor
Added by the BEAGLE.DO WORM! |
 |
RegPowerClean.exe |
RegPowerClean
RegistryPowerCleaner misleading secuirty software - not recommended, see here |
 |
Regprot.exe |
RegProt
RegistryProt from Diamond Computer Systems - protects the system registry against changes |
 |
REGPTMENS.EXE |
Regptmens
Added by the BANCOS-ED TROJAN! |
 |
rundll132.exe |
Regro
Added by the OKARAG TROJAN! |
 |
regeditt.exe |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
rundll32.exe |
Regrx
Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). The file is located in C:Windows |
 |
regscanr.exe |
Regscan
Added by the OPTIX-SE TROJAN! |
 |
Regscan.exe |
RegScan
Added by the TALEX TROJAN! |
 |
regserve.exe |
RegServer
Related to XGI Technology's Volari graphics cards - what does it do and is it required? |
 |
regservices.exe |
regservices.exe
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
regshave.exe |
RegShave
Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly |
 |
regsrv.exe |
regsrv
Added by the OPTIXPRO.11 TROJAN! |
 |
RegSrv64D.exE |
RegSrv64D
Added by the WINKO.AO WORM! |
 |
regsrvc.exe |
regsrvc
Added by the STOPED-A TROJAN! |
 |
regsv.exe |
Regsv
Search hijacker - redirecting to scheo.com |
 |
regsv.exe |
Regsvc
Added by an unidentified TROJAN! |
 |
regsvc32.exe |
regsvc32
Homepage hijacker that changes your homepage to an adult content site |
 |
regsvr.exe |
regsvr
Added by the WEBMONEY-G TROJAN! |
 |
regsvr32.exe ctasio.dll |
REGSVR32
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
regsync.exe |
regsync
SafeSurfing adware |
 |
RegTwk.exe |
RegTweak
Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface |
 |
REGVER.EXE |
RegVer
Added by the LATINUS.16 TROJAN! |
 |
Regverif32.exe |
RegVfy32
Added by the SYGYP.A WORM! |
 |
Regsysw.com |
Reg_WFT
Added by the WILSEF VIRUS! |
 |
RRAM.exe |
ReleaseRAM
"Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
reload.vbs |
reload
Added by the LOVELETTER.AS VIRUS! |
 |
reload.exe |
Reload
Added by the LAZAR TROJAN! |
 |
Remhelp.exe |
RemHelp
BT Voyager ADSL Modem Help related |
 |
reminder.exe |
Reminder
From MS Money. Reminds you of your bills |
 |
Remind_XP.exe |
Reminder
HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
 |
Reminder.exe |
Reminder
Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2 |
 |
remind32.exe |
Reminder-cpqXXXXX
Compaq printer Registration |
 |
remind32.exe |
Reminder-hpcXXXXX
HP CD-Writer Registration |
 |
remind32.exe |
Reminder-ranXXXXX
Registration reminder widget for Rand Mcnally maps |
 |
remind32.exe |
reminder-ScanSoft Product Registration
Registration reminder for ScanSoft products such as PaperPort |
 |
RemindMe.exe |
RemindMe
Remind-Me - calendar software |
 |
Remind_XP.exe |
Remind_XP
HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
 |
Remote.exe |
Remote
Remote Control driver for LifeView internal and external TV products |
 |
rnaapp.exe |
Remote Access
Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed |
 |
rvasvc.exe |
Remote Access Adapter
Detected by PCTools as the IRCBOT.BIF TROJAN! See here |
 |
rswsvc.exe |
Remote Access Domain
Added by the IRCBOT.BFA TROJAN! |
 |
rpgsvc.exe |
Remote Access Monitor
Added by a variant of the IRCBOT TROJAN! See here |
 |
rasmngr.exe |
Remote Access Service Manager
Added by the AGOBOT.KU WORM! |
 |
rwosvc.exe |
Remote Access Tool
Added by a variant of the IRCBOT TROJAN! See here |
 |
Rc.exe |
Remote Control
Hinet Hi-Five ISP software |
 |
resmsvc.exe |
Remote Event System
Detected by Trend Micro as the IRCBOT.YF TROJAN! See here |
 |
remote master.exe |
remote master
Required if you want your ASUS Remote control to work at all. Available via Start -> Programs |
 |
rpc.exe |
Remote Procedure Call For Windows 32bit
Added by the RBOT-MD WORM! |
 |
RUNDLL32.EXE reg678.dll ondll_reg |
Remote Procedure Call Locator
Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rmasvc.exe |
Remote Storage Access
Added by a variant of the IRCBOT TROJAN! See here |
 |
rtsbsvc.exe |
Remote Terminal Task
Detected by Trend Micro as the IRCBOT.AUZ TROJAN! See here |
 |
RAUAgent.exe |
RemoteAgent
Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates" |
 |
RcMan.exe |
RemoteCenter
Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats |
 |
rmctrl.exe |
RemoteControl
Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
 |
RemoteAgent.exe |
Remote_Agent
Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs |
 |
Removecpl.exe |
Removecpl
Related to a Belkin 54Mbps Wireless Utility Control Panel applet |
 |
Removed.exe |
Removed.exe
GatorCheat - adware downloader |
 |
removeit.exe |
RemoveIT Pro XT
RemoveIT Pro from InCode Solutions - spyware, virus and malware removal tool |
 |
remstart.exe |
RemStart
Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required? |
 |
repl.exe |
repl
Added by the YABE.CD TROJAN! |
 |
ReplayRadio.exe |
Replay Center
Replay Radio - "makes it easy to automatically record your favorite radio shows, so you can listen wherever and whenever you like" |
 |
RepliGoMon.exe |
RepliGo Assistant
Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device" |
 |
requester.*.exe |
requester
Added by a variant of the MUQUEST.A trojan - NOTE: the * stands for a digit, examples: requester.5.exe, requester.10.exe |
 |
requester.11.exe |
Requester
Added by the MUQUEST TROJAN! |
 |
restun.exe |
resagnt
Adware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ |
 |
ResChanger2004.exe |
ResChanger2004
EVGA graphic card utility providing easy access to display settings |
 |
rsrcmtr.exe |
Resource Meter
Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes |
 |
RestoreDesktop.exe |
RestoreDesktop
Softwarium Restore Desktop "is a Windows Context Menu addition that automatically saves and restores the icons' positions on the Windows desktop after a resolution change" |
 |
restory.exe |
restory
Added by the RETSAM TROJAN! |
 |
resumefix.exe |
ResumeFixClocks
Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards |
 |
retime.exe |
retime
Added by the GIPMA TROJAN! |
 |
retrieverscheduler.exe |
RetrieverScheduler
80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available |
 |
RetroExpress.exe |
RetroExpress
EMC (was Dantz) Retrospect Express - backup software for external hardware storage devices |
 |
RevoTask.exe |
RevoTaskbarApp
Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available |
 |
rexsymon.exe |
RexSyMon
Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC |
 |
rfagent.exe |
rfagent
Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders |
 |
RFTRay.exe |
RFTray
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
 |
Rfw.exe |
rfw
RAV AntiVirus |
 |
rfwmain.exe |
RfwMain
Rising antivirus |
 |
rfwydg.exe |
rfwydg
?? |
 |
rundll32.exe npvpg005.dll |
RFX_auto_upgrade
A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade |
 |
Rg2catbd.exe |
Rg2catbd
Added by a variant of the BANLOAD family of TROJANS! |
 |
rh32.exe |
RH
EuroFonts - adds Euro symbols to pre-Euro computers |
 |
RhinoBlocker.exe |
RhinoBlocker
RhinoBlocker - pop-up stopper |
 |
RHPTray.exe |
RHPTray
System tray access to Red Hot Pawn - online chess |
 |
rundll32.exe [path] hbcast.dll, WaitWindows |
RichMedia
Henbang adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
richup.exe |
richup
SafeSurfing adware |
 |
rcenterrll.exe |
Ring Central Fax
Only needed if you want a PC to answer faxes automatically |
 |
rIOPHosIs.vBS |
rIOphosIs
Added by the RIOSYS MACRO! |
 |
riomgr.exe |
Riorad Manager
"Riorad Explorer is hands-down the most advanced Windows software companion for your Rio MP3 player" |
 |
RivaTuner.exe |
RivaTuner
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
 |
RivaTuner.exe |
RivaTunerStartupDaemon
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
 |
RKLauncher.exe |
RK Launcher
RK Launcher by RaduKing - "is a free application that will allow the user to have a visually pleasing bar at the side of the screen that is used to quickly launch shortcuts" |
 |
rmctrl.exe |
rmctrl
Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
 |
rundll32.exe rmdrfje.dll, [random characters] |
rmdrfje.dll
Added by the DLOADR-ANM TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rmdrfje.dll" file is located in the Winnt or Windows folder |
 |
regsvr32.exe rmoc3260.dll |
rmoc3260.dll OCX
A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The "rmoc3260.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RmRemote.exe |
RMremote
Remote control driver for REALmagic Xcard. Is it required? |
 |
rndll2.exe |
rndll2
May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within? |
 |
rnxqh.exe |
rnxqh
?? |
 |
RoboTaskBarIcon.exe |
RoboForm
Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin |
 |
RoboFormWatcher.exe |
RoboFormWatcher
Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs |
 |
RocketTime.exe |
Rocket.Time
Rocket.Time - time synchronization software from Rocket Software |
 |
RocketDock.exe |
RocketDock
"RocketDock is a smoothly animated, alpha blended application launcher. It provides a nice clean interface to drop shortcuts on for easy access and organization" |
 |
RogueRemoverPRO.exe |
RogueMonitor
Rogue Remover PRO - utility to detect and remove misleading security programs masqerading as virus scanners, spyware removers, etc that lure people into buying them with false positives |
 |
rpclient.exe |
roketpipe
?? |
 |
RollbackTray.exe |
Rollback
Added by the RollBack Rx system restore program |
 |
ROUTD.exe |
ROUTD
?? |
 |
Router.exe |
Router
Detected by Kaspersky as the AGENT.FJN TROJAN! See here |
 |
RoxAssist.exe |
RoxAssist
Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel"). Can be run manually |
 |
RxMon.exe |
RoxioAudioCentral
Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly. |
 |
RoxWatchTray.exe |
RoxWatchTray
System Tray icon installed by Roxio Easy Media Creator 8 and which allows you to configure your watched folders or to turn the ?Watched Folders? feature of Roxio ON or OFF |
 |
rp32.exe |
RP32
Unicenter Remote Control (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems |
 |
rpcall.exe |
RPC Drivers
Detected by Trend Micro as the SDBOT.FLY WORM! See here |
 |
rpcc.exe |
rpcc
Added by the SPAMMIT-E TROJAN! |
 |
rpcda.exe |
rpcda Win32
Added by the RBOT-AE WORM! |
 |
rpcss.exe |
RPCSS.exe
Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here |
 |
rpcxwinex.exe |
RpcxWindows Extensions
Added by the RBOT.ACP WORM! |
 |
rundll32.exe |
Rr2
Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in an "addins" sub-folder |
 |
rrmedic.exe |
RRMedic
Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection |
 |
rscmpt.exe |
rscmpt
Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status |
 |
rsmb.exe |
rsmb
Added by the WAREZOV.C WORM! |
 |
rsMenu.exe |
rsMenu
Synchronizes a Casio PDA with MS Outlook |
 |
RSRCMTZ.exe |
RSRCMTZ
?? |
 |
rsrvmon.exe |
rsrvmon.exe
Detected by Kaspersky as the AGENT.NY TROJAN! See here |
 |
rundll32 RSSToolbar.dll, DllRunMain |
RSS
"Related Sites" toolbar - SearchAndClick hijacker variant |
 |
RssReader.exe |
RssReader
RssReader - a free RSS reader able to display any RSS and Atom news feed (XML) |
 |
rtasks.exe |
rtasks
Misleading security software such as AntiSpywareSuite, AntivirusPCSuite, SpyGuardPro, WinAntiVirus Pro 2006 - not recommended, see here |
 |
rtcdll.exe |
rtcdll
RTCDLL is "Real Time Communication" and is associated with Windows Messenger (the IM application, not messenger service). It is only necessary if you use Windows Messenger. Most people use MSN Messenger instead, so it is not required in those cases |
 |
RTHDCPL.EXE |
RTHDCPL
Realtek HD Audio Sound Effect Manager |
 |
RtHDVCpl.exe |
RtHDVCpl
High definition audio codec driver from Realtek Semiconductor |
 |
rtl.exe |
rtl.exe
Added by the TIOTUA-J TROJAN! |
 |
RtlMon.exe |
RtlMon.exe
Monitor for RealTek network card |
 |
RTMonitor.exe |
RTMonitor
Cheyenne (now eTrust) antivirus |
 |
rtos.exe |
rtos
IRC trojan |
 |
RTVSCN95.EXE |
rtvscn95
Real-time virus scanner component of Norton Anti-Virus Corporate Edition |
 |
RtWLan.exe |
RtWLan
Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
 |
RubeL.exe |
RubeL
Added by the RUBY-B TROJAN! |
 |
Ruby13.exe |
Ruby13
Added by the MEXER.E WORM! |
 |
Ruby14.exe |
Ruby14
Added by the FIGHTRUB-A WORM! |
 |
RuLaunch.exe |
RuLaunch
Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
 |
real.exe |
Run
Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
rundll32.exe rsrc.dll |
run
Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll_32.exe |
Run05
Added by the BANCOS-DT TROJAN! |
 |
run32dll.exe |
run32
Added by the SDBOT-CWB WORM! |
 |
ramsys.exe |
run=
Advanced Startup Manager from Rays Lab |
 |
RAVMOND.exe |
run=
Added by the LOVGATE-F WORM! |
 |
RegistryReminder.exe |
run=
Added by the APSTROJAN.OB TROJAN! |
 |
runAP.exe |
runAP
Not required but what is it? |
 |
Runapp32.exe |
Runapp32
Added by the NEODURK TROJAN! |
 |
Rund11.EXE |
Rund11
Added by the MARIO-C WORM! |
 |
rund1132.exe |
rund1132
Added by the DOPBOT-A WORM! |
 |
Rund1132.exe |
Rund1132.exe
Added by the STARTPA-HS TROJAN! |
 |
runddl.exe |
runddlfile
Added by the DELF.D TROJAN! |
 |
runlli32.exe |
Rundil32
Added by the QQPASS-U TROJAN! |
 |
rundli32.exe |
rundli32
Added by the LADE WORM! |
 |
rundll32.exe bridge.dll, Load |
RunDLL
Flingstone.com browser hijacker. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qkoszvd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Rundll~.exe |
Rundll
Added by the DELF-KT TROJAN! |
 |
rundll32.exe [random filename].dll |
Rundll
Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RunDll.exe |
RunDll
Added by the QQPASS-AH TROJAN! Note - this is NOT the Windows system file of the same name as described here |
 |
rundll.exe |
RunDLL Kernel File Core
Added by a variant of the SLAPER TROJAN! |
 |
Rundll16.exe |
Rundll16
Added by a number of VIRUSES, WORMS and TROJANS! |
 |
Rundll32.exe |
Rundll32
Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the WindowsFonts directory |
 |
RUNDLL32.EXE NvQtwk, NvCplDaemon |
RUNDLL32
System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here) |
 |
RunDLL32.exe NvMCTray.dll, NvTaskbarInit |
RunDLL32
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
 |
Rundll32.exe Wf2kcpl.dll DllLoadDefaultSettings |
rundll32
Loads default settings for Leadtek Winfast graphics cards |
 |
Rundll32.exe ptipbm.dll, SetWriteBack |
Rundll32
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller |
 |
rundll32.exe ptipbmf.dll, SetWriteCacheMode |
rundll32
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
 |
rundll32.exe |
rundll32
Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This one is is located in the Winnt or Windows folder |
 |
RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent |
rundll32
Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup |
 |
rundl32.exe |
RUNDLL32
Added by the DEMOTRY-A WORM! |
 |
rundll32.exe |
rundll32
Added by the AGENT-EZ TROJAN! Note - the real rundll32.exe resides in the System (9x/Me) or System32 (NT/2K/XP) folder whereas this file is found in a "SHELLEXT" subfolder |
 |
RUNDDLL32.EXE |
Rundll32
Added by the STARTPAGE.AXH TROJAN! |
 |
rookie.vbs |
rundll32
Added by the ROOKIE-A TROJAN! |
 |
rundll64.exe |
rundll32
Added by the DELF.BKC TROJAN! |
 |
Rundll32 cmicnfg.cpl, CMICtrlWnd |
Rundll32 cmicnfg
System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
 |
RunDll32 essprops.cpl, TaskbarIconWnd |
RunDll32 essprops
Associated with a Logitech mouse - required for proper operation |
 |
Rundll32 P17.dll, P17Helper |
Rundll32 P17
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
Root.exe |
Rundll32.exe
Added by the GRUEL WORM! |
 |
rundll32.exe MSIEFR40.DLL, DllRunServer |
Rundll32_7
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe inetp60.dll, DllRunServer |
Rundll32_8
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe 1.dll, DllRunServer |
Rundll32_8
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll.exe |
RundllSvr
Added by the HUAYU WORM! Note - this is NOT the Windows system file of the same name as described here |
 |
Rundllsystem32.exe |
Rundllsystem32
Added by the NETDEVIL.B TROJAN! |
 |
Rundnm.exe |
Rundnm
Added by the DELF-HA TROJAN! |
 |
retadpu.exe |
runner1
Added by the AGENT.SLZ TROJAN! |
 |
retadpu[random digits].exe |
runner1
Added by the SMALL.CTV TROJAN! |
 |
RUNONCE.EXE |
RunOnce
Part of MS Data Access Components - only required if you use these |
 |
runouce.exe |
Runonce
Added by the CHIR-B WORM! |
 |
run.exe |
runs
Added by the RBOT-BWF WORM! |
 |
runsvc32.exe |
RunServices
Added by the AGOBOT.QJ WORM! |
 |
runsql.exe |
runsql
Detected by PCTools as the DELF.ZWK TROJAN! See here |
 |
runsvc.exe |
runsvc
Added by the SMALL-CF TROJAN! |
 |
RunSysd32.exe |
RunSysd32
DesktopShield2000 by St?phane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within |
 |
runtime.exe |
runtime.exe
Added by a variant of the Tibs malware |
 |
runwin32.exe |
runwin32
Added by the ESEARCH-A TROJAN! |
 |
runwin32.exe |
RUNWIN32
Added by the VB-AET TROJAN! |
 |
Run_cd.exe |
Run_cd
Added by the GHOST.23 TROJAN! |
 |
Rupsw32.exe |
Rupsw32
MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems |
 |
rundll32.exe RUSBHOLoader.dll, AutoRegister |
RUSBHOLoader
?? |
 |
rundll32.exe |
rx
Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is found in the Windows or Winnt folder |
 |
rxmon9x.exe |
RxMon
Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" |
 |
RxUser.exe |
RxUser
Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" |
 |
rydanmxe.exe |
rydanmxe.exe
Added by the DLOADR-AZZ TROJAN! |
 |
rundl132.exe |
ryy
Added by the PWS-ANA TROJAN! |
 |
rundll32.exe |
rzt
Added by the LINEAGE.BDP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is found in an "Intel" sub-folder of the Windows or Winnt folder |
 |
r_server.exe |
r_server
Radmin - remote admistrator server |
 |
RegCon.exe |
SAClient
AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging |
 |
regsvr32 sfgupd.dll |
SafeGuard Popup Blocker Updater
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "sfgupd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
regsvr32 sfg****.dll [* = ramdom char] |
SafeGuard Popup Blocker Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
regsvr32 sfg****.dll [* = random char] |
SafeGuard Popup Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
regsvr32 PDF****.dll [* = random char] |
SafeGuard Popup Updater (required)
SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe sasync.dll, SyncWait |
saSyncMgr
Browser hijacker - redirecting to Searchant.com. Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup". Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe savsvc.dll,start |
Savsvc
Added by the AKBOT.BE WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "savsvc.dll" file is found in %System% |
 |
RYZO32.EXE |
SB13mini
Added by the SPYBOT-EJ WORM! |
 |
RunDll32 sbusbdll.dll, RCMonitor |
SbUsb AudCtrl
Control for Soundblaster MP3 external (USB) sound card |
 |
run.exe |
sc
All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
ScreenSaverPlus
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
Regedit32.com |
Secure64
Detected by Symantec as the SILLYFDC WORM! See here |
 |
regeditnt.exe |
Service Registry NT Save
Added by the BANCOS-BM TROJAN! |
 |
rundll32.exe ptipbmf.dll, SetWriteCacheMode |
SetCacheMode
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
 |
runt32.exe |
setupa
Added by the QQPASS-K TROJAN! |
 |
rnll32.exe |
setupdata
Added by the QQPASS-AC TROJAN! |
 |
regedit.exe setupuser.log |
setupuser
Regfile in disguise - another CoolWebSearch parasite variant |
 |
rayiou.exe |
SfKg6w
Added by the AGENT.BUO WORM! |
 |
ray.exe |
Shell
Homepage hijacker re-directing browsers to adult content websites |
 |
Ruden.vbs |
Showme
Added by the HANDLE-A VIRUS! |
 |
rundll32.exe si91e44b.dll, EnableRunDLL32 |
si91e44b
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "si91e44b.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Rundll32.exe SiSPower.dll, ModeAgent |
SiSPower
Responsible for power management for SIS chipsets - is it required? |
 |
remotehost.pif |
Sistray32
Added by the HOLCAS.A WORM! |
 |
rnxntup.exe |
sjduwiwx
Added by a variant of the ORCU.B TROJAN! |
 |
rbot32.exe |
sl4 rules
Added by the SDBOT-QC WORM! |
 |
runtime.exe |
smrtdrv
Added by the AGOBOT.MT WORM! |
 |
Rwon.exe |
Soar
PurityScan/Clickspring adware |
 |
rpcxsocsa.exe |
Social Security Agency
Added by a variant of the RBOT WORM! |
 |
rcea.exe |
Soot
?? |
 |
rundll32 shell32.dll, ShellExec_RunDLL [path] soproc.exe |
SOProc_RegSoAlertWxLiteNnAj
SoftwareOnline Intelligent Downloader - "Bundle engine to enable download of end user approved third party applications and reporting of installs for billing purposes only". Said to monitor user's browsing habits and display pop-up ads |
 |
rundll32 cwcprops.cpl |
SoundFusion
Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
 |
rundll32 hercplgs.cpl, BootEntryPoint |
SoundFusion
Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
 |
RunDll32 cwaprops.cpl, C25CrystalControlWnd |
SoundFusion
Control panel item for a Terratec soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
 |
regedit-s .... sp.dll |
sp
Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix |
 |
rundll32 (Path to Trojan DLL), DllInstall |
sp
Added by the ABLANK-W and ABLANK-Z TROJANS! |
 |
Rundll32.exe spads.dll |
spa_start
IconAds adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "spads.dll" file is located in the Winnt or Windows folder |
 |
Rundll32.exe sprt_ads.dll |
spa_start
AdRotator adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sprt_ads.dll" file is located in the Winnt or Windows folder |
 |
Rundll32 SPIRun.dll, RunDLLEntry |
SPIRun
Related to Creative audio products. What does it do and is it required? |
 |
run.exe |
SPP
?? |
 |
regedit -s spp.reg |
spp
IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/ |
 |
Remove_spyware.exe |
Spyware remover
Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related! |
 |
rundll32.exe sre.dll, Register |
sre
CoolWebSearch parasite variant - also detected by Kaspersky as the AGENT.FC TROJAN! |
 |
rundll32.exe [path] srescan.dll, DoSpecialAction |
srePostpone
Related to ZoneAlarm. What does it do and is it required? |
 |
rundll32 srclient.dll, CreateFirstRunRp |
SRFirstRun
Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup? |
 |
runsrv32.exe |
Srv32 spool service
Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN! |
 |
RunWinRaR.exe |
startkey
Added by a variant of the BIFROSE-LV TROJAN! |
 |
royale.exe |
startkey
Added by a variant of the SDBOT WORM! |
 |
rtfmsv.exe |
startkey
Added by the EDEPOL-C TROJAN! |
 |
rundle2.exe |
startwindowskeyuser
Added by the JAVAKILLER TROJAN! |
 |
rundll32exe stlbdist.DLL, DllRunMain |
stlbdist
Hijacker pointing to www.searchandclick.com |
 |
rundll32.exe stlbupdt.DLL, DllRunMain |
stlbupdt
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe supdate2.dll |
supdate2.dll
Added by the ZLOB-VL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "supdate2.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32 [path] sbuddy.dll |
SurfBuddy
SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll16.exe |
svchost
Added by the STARTPA-PB TROJAN! |
 |
restore3.exe |
SvcManager
Added by the AGENT-DSS TROJAN! |
 |
rundll32.exe [path] SWL.dll rdl |
SWL
StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
regedit.exe |
Symantec Antivirus professional
Added by a variant of the FORBOT WORM! |
 |
rservers.exe |
Synchronization Manage
Added by the FORBOT-FM WORM! |
 |
regedit /s sys.reg |
sys
Hijacker |
 |
regedit sysdllwm.reg |
sys
CoolWebSearch parasite variant - also detected as the FEMAD-L TROJAN! |
 |
Runddll32.exe |
SysDeskqqfx
Added by the CHANGGAME TROJAN! |
 |
rpcmon.exe |
Sysmon
Added by the RANDEX.ATX WORM! |
 |
rundll32 setupapi, InstallHinfSection [varies] oemsyspnp.inf |
SysPnP
CoolWebSearch PnP parasite variant |
 |
Regedit.exe -s pcsearch.reg |
SysSearch
Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "pcsearch.reg" file is located in the Winnt or Windows folder |
 |
Regedit.exe -s sysreg.reg |
SysSearch
Added by the STARTPA-ME TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The "sysreg.reg" file is located in the Winnt or Windows folder |
 |
run322.exe |
System
Added by the LANFILT TROJAN! |
 |
regedit -s system.dll |
system
Homepage hijacker |
 |
Rundll32.exe SysDll32.dll, SystemCheck |
System Check
XPCSpy Pro keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Regsrv.exe |
System Profile
Added by a variant of the OPTIX TROJAN! |
 |
rebootsys.exe |
System Reboot
Added by the RBOT-WU WORM! |
 |
rpcxcmod.exe |
System Setup
Added by an unidentified WORM or TROJAN! |
 |
rundll32.exe [path] SystemKey.dll rdl |
SystemKey
Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32.exe beem.dll, DllRegisterServer |
Systems Restart
Browser hijacker - the file serves to register a dll implemented as a browser plugin. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32.exe snim.dll, DllRegisterServer |
Systems Restart
Added by the STARTPAGE.I TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32.exe zolk.dll, DllRegisterServer |
Systems Restart
Added by a variant of the STARTPAGE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32.exe boln.dll, DllRegisterServer |
Systems Restart
Added by the STARTPAGE.J TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
regedit.exe -s c:ie.reg |
SystemSearch
Installs a Seachxl.com browser page hijack |
 |
regedit.exe -s c:sys.reg |
SystemSearch
Installs a i--search.com browser page hijack |
 |
rundll32.exe [path] SystemWeb.dll rdl |
SystemWeb
StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe |
SysWy
Added by the LINEAGE-JH TROJAN! Note - this file is found in the C:WindowsSystem folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win98/ME systems, and in the WinntSystem32 or WindowsSystem32 folder in WinXP/NT/2K! |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
TakeMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
razerhid.exe |
Tarantula
Razer Tarantula gaming keyboard driver |
 |
regsvc32.exe |
Task Commander
Added by the AGOBOT-RX WORM! |
 |
RunDLL deskcp16.dll, QUICKRES_RUNDLLENTRY |
Taskbar Display Controls
Only appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel -> Display -> Settings -> Advanced -> General. Also appears if you have Win95 with the QuickRes "Powertoy" installed |
 |
Rund1.exe |
Taskbell.exe
Added by the YIPID TROJAN! |
 |
rundll32.exe |
TaskMan
Added by the DVLDR TROJAN! Note - this is not the valid "rundll32.exe" as it's in the WindowsFonts directory |
 |
Rund1132.exe qq.dll, Rundll32 |
Tencent QQ
Added by the QQPASS.F TROJAN! |
 |
rundll32 [path] RyDial.dll, QuickStart |
Tesco.net
Tesco.net dial-up ISP software - not required |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
TheBestMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
realsched.exe |
TkBell.Exe
Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK |
 |
realsched.exe |
TkBellExe
Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK |
 |
regedit ..tour.reg |
tour
Edits registry values to keep the WinMe tour in Task Scheduler |
 |
regedit /s [path] tour.reg |
tourpath
Edits registry values to keep the Win 2000 "tour" in Task Scheduler |
 |
rundll32.exe transys.dll,start |
transys
Added by the AKBOT-AE WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "transys.dll" file is found in %System% |
 |
rundll32.exe |
Tray
Added by the LINEAG-ADR TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in an "command" sub-folder |
 |
Remote.exe |
TvrRemote
Remote Control driver for LifeView internal and external TV products |
 |
rundll32.exe tweakui.cpl, tweakmeup |
Tweak UI
Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed |
 |
rundll32.exe tweakui.cpl, tweaklogon |
Tweak UI
Automatically logs you on if you have Microsoft's Tweak UI "powertoy" installed |
 |
RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup |
Tweak UI
Added by the SUBWOOFER TROJAN! Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup". Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RUNDLL32.EXE TWEAKUI.CPL, TweakMeUp |
Tweak UI 1.33 deutsch
Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed - German version |
 |
rundll32.exe UCMTSAIE.dll, DllShowTB |
UCmore XP - The Search Accelerator
UCmore toolbar - search accelerator |
 |
rundll32.exe uhvjsul.dll, mrpmvyf |
uhvjsul.dll
Added by the BUSKY-G TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "uhvjsul.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RegistryBooster.exe |
Uniblue Registry Booster
Uniblue "Registry Booster is the safest and most trusted solution to clean and optimise your system, free it from registry errors and fragmented entries" |
 |
regsvr32 image.dll |
uninstal
CoolWebSearch parasite variant |
 |
r00t.exe |
update
Added by the RBOT-ACO WORM! |
 |
RAuth.exe |
UpDate
Added by the DLOADER-UL TROJAN! |
 |
ravseuper.exe |
Update.exe
Added by the QQPASS-P TROJAN! |
 |
Rundll32.exe |
UPDATEHOOK
?? |
 |
realupdate.exe |
updatereal
Chinese originated adware |
 |
rvupdmgr.exe |
updmgr
eUniverse/KeenValue adware |
 |
rpcxuisu.exe |
UserInit StartUp
Added by a variant of the SDBOT WORM! |
 |
rncr.exe |
Usrr
PurityScan/Clickspring adware |
 |
rpen.exe |
Usrr
PurityScan/Clickspring adware |
 |
rundll32.exe utasvc.dll,start |
utasvc
Added by the AKBOT-AB WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "utasvc.dll" file is found in %System% |
 |
Rundll32.exe v128iitw.dll, STB_InitTweak |
V128IID
Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages |
 |
regsvr32.exe vernn16.dll |
vern16.dll
DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "vernn16.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RUNDLL32.exe MSSIGN30.DLL ondll_reg |
VFW Encoder/Decoder Settings
Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RsrVga32.exe |
VgaDriver
Added by the KEYLOG-AH TROJAN! |
 |
rundll32.exe 3DBBps.dll, BansheeLoadSettings |
VoodooBanshee
Loads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not |
 |
reg.exe |
vuaaa
Added by a variant of the RBOT WORM! |
 |
rundll32.exe w3knet.dll, dllinitrun |
W3KNetwork
Web3000 adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
raagtapp.exe |
WebExRemoteAccessAgent
Related to Web Meetings from WebEx Communications, Inc. Share and present online with anyone, anywhere |
 |
rundll32 [path] webspec.dll |
WebSpecials
WebSpecials spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RtlWake.exe |
WG111v2 Smart Wizard Wireless Setting
Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
 |
RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu |
WIAWizardMenu
Still Image Class Installer - installed with a webcam |
 |
RUNDLL32.exe cdaEngine0400.dll, cdaEngineMain |
WildTangent CDA
Part of the WildTangent on-line games system. What does it do and is it required? |
 |
regedit -s ..win.dll |
win
Added by the SEEKER.K TROJAN! |
 |
Rundll32.exe |
Win32 Rundll Loader
Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file! |
 |
rundll16.exe |
Win32 USB2.0 Driver
Added by the WOOTBOT.H WORM! |
 |
rundll32.exe [Temp][ORIGFILENAME].DLL, InstallLaunchEv |
winabc
Added by the LINEAGE-PN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe wincls.dll,start |
wincls
Added by the AKBOT-AR WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincls.dll" file is found in %System% |
 |
rundll32.exe algs.exe,start |
WinDLL (algs.exe)
Detected by Kaspersky as the AKBOT.E BACKDOOR! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "algs.exe" file is found in %System% |
 |
rundll32.exe asdfsa.exe,start |
WinDLL (asdfsa.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "aqls32.exe" file is found in %System% |
 |
rundll32.exe bee.dll,start |
WinDLL (bee.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bee.dll" file is found in %System% |
 |
rundll32.exe bix.exe,start |
WinDLL (bix.exe)
Detected by Kaspersky as the KOLAB.OL WORM! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bix.exe" file is found in %System% |
 |
rundll32.exe CSMSS.EXE,start |
WinDLL (csmss.exe)
Added by the AKBOT.U WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "CSMSS.EXE" file is found in %System% |
 |
rundll32.exe ctfmonm.exe,start |
WinDLL (ctfmonm.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ctfmonm.exe" file is found in %System% |
 |
rundll32.exe dasda.com,start |
WinDLL (dasda.com)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dasda.com" file is found in %System% |
 |
rundll32.exe diem.exe,start |
WinDLL (diem.exe)
Added by the AKBOT.E WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "diem.exe" file is found in %System% |
 |
rundll32.exe dlfksdld.exe,start |
WinDLL (dlfksdld.exe)
Detected by Kaspersky as the IRCBOT.BPM TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dlfksdld.exe" file is found in %System% |
 |
rundll32.exe jbi32.dll,start |
WinDLL (jbi32.dll)
Added by the AKBOT.E WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jbi32.dll" file is found in %System% |
 |
rundll32.exe lcass.exe,start |
WinDLL (lcass.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "lcass.exe" file is found in %System% |
 |
rundll32.exe mysnlive.exe,start |
WinDLL (mysnlive.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mysnlive.exe" file is found in %System% |
 |
rundll32.exe qwex.dll,start |
WinDLL (qwex.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qwex.dll" file is found in %System% |
 |
rundll32.exe redyLive.exe,start |
WinDLL (redyLive.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "redyLive.exe" file is found in %System% |
 |
rundll32.exe scvhost32.dll,start |
WinDLL (scvhost32.dll)
Added by the AKBOT.M WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "scvhost32.dll" file is found in %System% |
 |
rundll32.exe slmss.exe,start |
WinDLL (slmss.exe)
Added by the AKBOT.AW WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slmss.exe" file is found in %System% |
 |
rundll32.exe slsass.exe,start |
WinDLL (slsass.exe)
Detected by Kaspersky as the AKBOT.E TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slsass.exe" file is found in %System% |
 |
rundll32.exe smaprnter.exe,start |
WinDLL (smaprnter.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "redyLive.exe" file is found in %System% |
 |
rundll32.exe sslms.exe,start |
WinDll (sslms.exe)
Added by the AKBOT-AS WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sslms.exe" file is found in %System% |
 |
rundll32.exe start0s.exe,start |
WinDLL (start0s.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "start0s.exe" file is found in %System% |
 |
rundll32.exe steam.dll,start |
WinDLL (steam.dll)
Added by the AKBOT.M WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "steam.dll" file is found in %System% |
 |
rundll32.exe svc.exe,start |
WinDLL (svc.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svc.exe" file is found in %System% |
 |
rundll32.exe svchost.dll,start |
WinDLL (svchost.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svchost.dll" file is found in %System% |
 |
rundll32.exe sysx32.dll,start |
WinDLL (sysx32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sysx32.dll" file is found in %System% |
 |
rundll32.exe tepmlayer.exe,start |
WinDLL (tepmlayer.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tepmlayer.exe" file is found in %System% |
 |
rundll32.exe tmp.exe,start |
WinDLL (tmp.exe)
Detected by Kaspersky as the KOLAB.L WORM! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tmp.exe" file is found in %System% |
 |
rundll32.exe tock24.dll,start |
WinDLL (tock24.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tock24.dll" file is found in %System% |
 |
rundll32.exe tqurity.exe,start |
WinDLL (tqurity.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tqurity.exe" file is found in %System% |
 |
rundll32.exe v4mon.dll,start |
WinDLL (v4mon.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "v4mon.dll" file is found in %System% |
 |
rundll32.exe vdm32.dll,start |
WinDLL (vdm32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vdm32.dll" file is found in %System% |
 |
rundll32.exe vxd32.dll,start |
WinDLL (vxd32.dll)
Added by the AKBOT.R WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vxd32.dll" file is found in %System% |
 |
rundll32.exe wchshield.exe,start |
WinDLL (wchshield.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wchshield.exe" file is found in %System% |
 |
rundll32.exe wimimi.exe,start |
WinDLL (wimimi.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wimimi.exe" file is found in %System% |
 |
rundll32.exe windns32.dll,start |
WinDLL (windns32.dll)
Detected by Kaspersky as the AKBOT.E WORM! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tmp.exe" file is found in %System% |
 |
rundll32.exe wingatey32.exe,start |
WinDLL (wingatey32.exe)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wingatey32.exe" file is found in %System% |
 |
rundll32.exe wintmp.exe,start |
WinDLL (wintmp.exe)
Detected by Kaspersky as the AKBOT.E BACKDOOR! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wintmp.exe" file is found in %System% |
 |
rundll32.exe wsync32.dll,start |
WinDLL (wsync32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wsync32.dll" file is found in %System% |
 |
rundll32.exe xvd32.dll,start |
WinDLL (xvd32.dll)
Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "xvd32.dll" file is found in %System% |
 |
run.exe |
Windows
Added by the SPYBOT.OFN WORM! |
 |
rge.exe |
Windows ASN Service
Added by the RBOT-AOK WORM! |
 |
runddls.exe |
Windows AutomaticUpdater
Added by a variant of the RBOT WORM! |
 |
RUNDLL.EXE |
Windows Config
Added by the SPYBOT-DX WORM! Note - this is not the Windows system file of the same name as described here |
 |
RUNDLL16.EXE |
Windows DLL Loader
Added by the DOMWIS TROJAN! |
 |
rundll32.exe |
Windows DLL Loader
Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process |
 |
rundll32.exe |
Windows Firewall
Added by a variant of the IRCBOT BACKDOOR! |
 |
RunDLL32.exe ehuihlp.dll, BootMediaCenter |
Windows Media Center
Starts Windows Media Center every time Windows Vista (Home Premium or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center -> Tasks -> Settings -> General -> Startup and Window Behaviour |
 |
registr32.exe |
WINDOWS REGISTER EDIT
Added by an unidentified WORM or TROJAN! |
 |
regexpress.exe |
Windows Registry Express Loader
Added by the FORBOT-CJ WORM! |
 |
RegistryRepairPro.exe |
Windows Registry Repair Pro
Registry Repair Pro. "Scans the Windows Registry for invalid or obsolete information in the registry" |
 |
regscan32.exe |
Windows Registry Scan
Added by the RBOT.KE WORM! |
 |
regscan23.exe |
Windows Registry Scan
Added by a variant of the RBOT WORM! |
 |
regscan.exe |
Windows Registry Scan
Added by the RBOT-HA WORM! |
 |
regserv.exe |
Windows Registry Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
rundll128.exe |
Windows Running DLL Service
Added by a variant of the IRCBOT TROJAN! See here |
 |
rundll64.exe |
Windows Running DLL Service
Added by a variant of the IRCBOT TROJAN! See here |
 |
rundll32.vbe |
Windows Security Assistant
CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN! |
 |
r.exe |
Windows Service
Added by a variant of the SMALL.VZ TROJAN! |
 |
regs32.exe |
Windows Services Agant
Added by the SDBOT-DIK WORM! |
 |
Realplayer.exe |
Windows SYSTEM32
Added by the SPYBOT.ZH WORM! |
 |
rmbsvc.exe |
Windows Terminal Manager
Added by a variant of the IRCBOT TROJAN! |
 |
rundlI32.exe |
Windows TM
Added by a variant of the RBOT WORM! |
 |
rundll.exe |
Windows Upate
Added by the HAKO TROJAN! Note - this is NOT the Windows system file of the same name as described here |
 |
real.exe |
windows update
Added by the LEGMIR-AU WORM! |
 |
rempss.exe |
Windows Update 32
Added by the FORBOT-FW WORM! |
 |
rfkampig.exe |
Windows-TCP-IP
Added by the GIPMA TROJAN! |
 |
rundll.exe |
Windows32
Added by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Windows system file of the same name as described here |
 |
rkbuouoxfl.exe |
WindowsRegKey update
Added by the RBOT-OO WORM! |
 |
RPCX1sQ3.exe |
windowsupdate
Added by the IRCBOT.B TROJAN! |
 |
regserv.exe |
WindowsUpdateR
Added by the COBFINN_B TROJAN! |
 |
rundll32.exe oobefldr.dll, ShowWelcomeCenter |
WindowsWelcomeCenter
Shows the Welcome Center every time you boot into Windows Vista |
 |
Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings |
Winfast2KLoadDefault
Loads default settings for Leadtek Winfast graphics cards |
 |
Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings |
WinFast_Gamma
Loads if you change the gamma settings on Leadtek WinFast graphics cards |
 |
rundll32.exe wftask.dll, WFDllLoadDefaultSettings |
WinFast_Taskbar
Loads default settings for Leadtek WinFast graphics cards |
 |
rsswjzgp.exe |
WinFix service
Added by the RBOT-FAE WORM! |
 |
rundll32.exe wh95.dll, HackMe |
WinHacker
WinHacker tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free |
 |
realsched.exe |
WinHelp
Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System% |
 |
Rechnung.pdf.exe |
winldr
Added by the ACS TROJAN! |
 |
read.exe |
WinReader
Added by the DELBOT-V WORM! |
 |
remote.exe |
Winshell
Added by the MYTOB.LJ WORM! |
 |
RUN32DLL.exe |
winstro
Added by the FTP_ANA TROJAN! |
 |
RUNDLL32.EXE [random value].dll, _mainRD |
winupd
Added by the MOTA.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder |
 |
RBSKQQBO.EXE |
WinUpdate
Added by the VBSWG2B.A WORM! |
 |
RUNDLL32.EXE [random.dll] |
winupdt
Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder |
 |
Rundll32 LoadDll, LoadExe WinXPLoad.exe |
WinXPLoad
Compaq hotkey related - required if you use the hotkeys |
 |
rundll32.exe wm41a398.dll, EnableRunDLL32 |
wm41a398
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wm41a398.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe wmcbaaca.dll, EnableRunDLL32 |
wmcbaaca
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wmcbaaca.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe wrclib.dll,start |
wrclib
Added by the AKBOT-AH WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wrclib.dll" file is found in %System% |
 |
rpcxmn32.exe |
WSAConfiguration
Added by the AGOBOT.ABG WORM! |
 |
RegSvr32.exe |
WUx_RegSvr
x is any number?? |
 |
rnxntup.exe |
xibquxs
Added by a variant of the ORCU.B TROJAN! |
 |
RunDll32 InstZ82.dll, SetUsbPrinterPort |
xkstartup
On a system with a Lexmark printer |
 |
rnxntup.exe |
xmnfuruwk
Added by the ORCU.B TROJAN! |
 |
RVHOST.exe |
Yahoo Messengger
Added by the SILLYFDC-G WORM! |
 |
rundll32.exe MSA64CHK.dll, DllMostrar |
YourMP3
MatrixDialer related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in the Winnt or Windows folder |
 |
rundll32 CNBabe.dll, DllStartup |
Zenet
CommonName Toolbar spyware. To uninstall see here |
 |
rundll.exe ZIBMACC.INF |
ZIBMACC
ZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435) |
 |
Removeme.exe |
Zonealarm
Added by the FORBOT-BG WORM! |
 |
rnsys.exe |
Zonesoft Cleaner
Added by a variant of the SDBOT WORM! |
 |
rundll32.exe zsmscc071001.dll mymain |
zsmscc
Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "zsmscc071001.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Regsrv32.com |
[executed file name]
Added by the SOUTHGHOST WORM! |
 |
rsbmsc.exe |
[random characters]
Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN! |
 |
r?gsvr32.exe |
[random name]
PurityScan/Clickspring adware |
 |
r?ndll32.exe |
[random name]
PurityScan/Clickspring adware |
 |
r?gedit.exe |
[random name]
PurityScan/Clickspring adware |
 |
r?ndll.exe |
[random name]
PurityScan/Clickspring adware |
 |
rundl13a.exe |
[random name]
Added by the GAMPASS-L TROJAN! |
 |
runload32.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
RtlFindVal.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
rwwnw64d.exe |
{**-**-**-**-**}
Identified as a variant of the AdWare.Win32.ZenoSearch.am malware, where ** are random characters |
 |
rundll32.exe stlb2.dll, DllRunMain |
{12EE7A5E-0674-42f9-A76B-000000004D00}
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll32.exe stlbdist.dll, DllRunMain |
{2CF0B992-5EEB-4143-99C0-5297EF71F444}
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stlbdist.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
rundll32.exe stlbupdt.DLL, DllRunMain |
{2CF0B992-5EEB-4143-99C2-5297EF71F44B}
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stlbupdt.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |